{"id":7224,"date":"2025-02-06T09:00:00","date_gmt":"2025-02-06T15:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/cyber-savanna-rigged-race-you-cant-win-must-run-anyway"},"modified":"2025-02-06T09:00:00","modified_gmt":"2025-02-06T15:00:00","slug":"the-cyber-savanna-a-rigged-race-you-cant-win-but-must-run-anyway","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2025\/02\/06\/the-cyber-savanna-a-rigged-race-you-cant-win-but-must-run-anyway\/","title":{"rendered":"The Cyber Savanna: A Rigged Race You Can&#8217;t Win, but Must Run Anyway"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt176912dc707b7629\/67a4c7e02f8fd4d25a38e20a\/Gazelle_%281800%29_Daniel_Lamborn_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/the-cyber-savanna-a-rigged-race-you-cant-win-but-must-run-anyway.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/the-cyber-savanna-a-rigged-race-you-cant-win-but-must-run-anyway.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cybersecurity is a relentless, brutal, and unwinnable race. It&#8217;s a savanna where organizations are gazelles and threat actors are cheetahs. There&#8217;s no prize for coming first, no trophies for the fastest. It&#8217;s actually simple: Run or be eaten. Harsh? Yes. But ignoring this reality won&#8217;t save you. It&#8217;ll make you the slowest gazelle.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"You're Not Losing to Hackers \u2014 You're Losing to Complacency\">You&#8217;re Not Losing to Hackers \u2014 You&#8217;re Losing to Complacency<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Blaming hackers for breaches is a sign of avoidance. Yes, they&#8217;re relentless and innovate faster than most companies defend, but they&#8217;re not the reason your systems are wide open. That&#8217;s on you!<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Your real enemy is&nbsp;complacency. It&#8217;s the decision to rely on the legacy tools you have because upgrading feels &#8220;too disruptive.&#8221; It&#8217;s adopting buzzwords like &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/application-security\/shift-left-pushback-triggers-security-soul-searching\">shift-left security<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8221; without empowering developers to act on it and saying it doesn&#8217;t work. This isn&#8217;t about being perfect. It&#8217;s about not being the easiest target. And right now, too many organizations are making it too easy.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Did Anyone Say &quot;Shift Left&quot;?\">Did Anyone Say &#8220;Shift Left&#8221;?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Shift-left security is pitched as the savior of modern <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/application-security\">AppSec<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The promise? Catch vulnerabilities early in the development cycle when they&#8217;re cheapest to fix and pose no immediate risk. The reality? Most organizations are implementing it wrong or not at all.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Let&#8217;s be honest: When did you last see a developer voluntarily ask security to review their code? Developers are under constant pressure to write code and deliver fast. Security is often seen as an obstacle, not an ally. The result? Insecure code makes it to production, and shift-left becomes just another buzzword.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For shift-left to work, it needs to be invisible and automated. It needs to be Integrated seamlessly into developer workflows. Anything less is just wishful thinking and a sure-fire way to alienate your dev teams.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Ugly Truth: Companies Are Being Breached With Old Vulnerabilities\">The Ugly Truth: Companies Are Being Breached With Old Vulnerabilities<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The painful reality is that many organizations fall prey to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/decade-old-cisco-vulnerability-exploit\">cyberattacks exploiting vulnerabilities that were identified<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Those vulnerabilities should have been patched years ago. As of 2024, more than 200,000 vulnerabilities have been identified, with more than 40,000 new ones disclosed in 2024 alone, marking a relentless upward trend.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Even when focusing on the Cybersecurity and Infrastructure Security Agency&#8217;s (CISA&#8217;s) <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/monitoring-kev-list-for-changes-can-guide-security-teams\">Known Exploited Vulnerabilities<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, a list of around 1,250 vulnerabilities actively used in real-world attacks, the industry&#8217;s response paints a grim picture. According to Verizon&#8217;s &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/?cmp=knc:ggl:ac:ent:ea:na:8888855284_ds_cid_71700000082347933_ds_agid_58700006959920338&amp;utm_term=verizon%20dbir%202024&amp;utm_medium=cpc&amp;utm_source=google&amp;utm_campaign=GGL_BND_Security_Exact&amp;utm_content=Enterprise&amp;gad_source=1&amp;gclid=Cj0KCQiAwOe8BhCCARIsAGKeD54_BkSTuvLc1wpbOTN113J2DllUvRCFqI9nMkAdtNElppoJaMgDJ00aAglwEALw_wcB&amp;gclsrc=aw.ds\">2024 Data Breach Investigations Report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">,&#8221; only 15% of companies patch these vulnerabilities within the first 30 days of their inclusion on this critical list, and 8% remain unremediated even after a year.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This isn&#8217;t about sophisticated zero-day exploits. Attackers often take the path of least resistance, targeting unpatched, well-documented vulnerabilities with a proven track record of success. The issue is compounded by overburdened security teams, constrained resources, and increasingly complex IT infrastructures, all of which make timely patching a challenge.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">If you are slower, you will be breached. You could have prevented it, but due to complacency, misplaced priorities, or the inability to keep pace with the overwhelming number of vulnerabilities disclosed each year, you didn&#8217;t.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"So, Why Run at All?\">So, Why Run at All?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">If the race is unwinnable, what&#8217;s the point? The point is this: You can make the race work for you. Survival isn&#8217;t about perfection. It&#8217;s about prioritization. It&#8217;s about focusing on vulnerabilities that attackers can exploit in your environment and could significantly impact your organization. Concentrating your efforts here can make you a much tougher target, forcing attackers to move on to easier prey.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This isn&#8217;t a race to fix everything; it&#8217;s a race to focus on what matters. Smart prioritization is your edge.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Race You Can Win (If You Redefine Winning)\">A Race You Can Win (If You Redefine Winning)<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Here&#8217;s the good news: While you can&#8217;t &#8220;win&#8221; this race in the traditional sense, you can succeed within it. Winning isn&#8217;t about fixing every vulnerability or stopping every attack. It&#8217;s about managing risk effectively and making it harder for attackers to succeed.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The savanna may be brutal, but it rewards organizations that are resilient, adaptable, and focused on what matters most. By homing in on vulnerabilities that are critical risks to you based on their factual reachability, exploitability, and impact, you can deliver results without being overwhelmed by the sheer volume of threats.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yes, cybersecurity is hard, and the odds are stacked against you. But you&#8217;re not powerless. By embracing resilience, prioritizing critical vulnerabilities, and fostering collaboration across teams, you can make the race work for you.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In this savanna, you don&#8217;t have to be the fastest gazelle. You just can&#8217;t afford to be the slowest. So, run smart. Run strong. Focus on what matters. And whatever you do \u2014 don&#8217;t stop.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/cyber-savanna-rigged-race-you-cant-win-must-run-anyway\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY Cybersecurity is a relentless, brutal, and unwinnable race. It&#8217;s<\/p>\n","protected":false},"author":12,"featured_media":7225,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-7224","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/the-cyber-savanna-a-rigged-race-you-cant-win-but-must-run-anyway.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/the-cyber-savanna-a-rigged-race-you-cant-win-but-must-run-anyway.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/the-cyber-savanna-a-rigged-race-you-cant-win-but-must-run-anyway.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/the-cyber-savanna-a-rigged-race-you-cant-win-but-must-run-anyway.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/the-cyber-savanna-a-rigged-race-you-cant-win-but-must-run-anyway.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/the-cyber-savanna-a-rigged-race-you-cant-win-but-must-run-anyway.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/the-cyber-savanna-a-rigged-race-you-cant-win-but-must-run-anyway.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/the-cyber-savanna-a-rigged-race-you-cant-win-but-must-run-anyway.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/the-cyber-savanna-a-rigged-race-you-cant-win-but-must-run-anyway.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/the-cyber-savanna-a-rigged-race-you-cant-win-but-must-run-anyway.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/the-cyber-savanna-a-rigged-race-you-cant-win-but-must-run-anyway.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7224","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=7224"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7224\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/7225"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=7224"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=7224"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=7224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}